ZDI Drops 13 Unpatched Ivanti Zero-Days Enabling Remote Code Execution

The Zero Day Initiative (ZDI) has publicly disclosed 13 unpatched vulnerabilities in Ivanti Endpoint Manager, including twelve remote code execution (RCE) flaws and one local privilege escalation vulnerability. The advisories published yesterday detail exploitable flaws that Ivanti has yet to patch, despite months of advance notice and postponed timelines. ZDI has marked all 13 issues … Continue reading ZDI Drops 13 Unpatched Ivanti Zero-Days Enabling Remote Code Execution